logo

Checkmarx supply chain attack impacts Bitwarden npm distribution path

ID: 51979f70-20c9-561b-befa-7f8b2fc04b5a

STIX ID: report--51979f70-20c9-561b-befa-7f8b2fc04b5a

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-04-24

Date Updated: 2026-04-26

Author: Pierluigi Paganini

...
...

Researchers report that the Checkmarx supply-chain campaign briefly compromised the Bitwarden CLI npm distribution (version 2026.4.0) via a malicious preinstall hook introduced by a compromised GitHub Action; the multi-stage payload harvests SSH keys, cloud credentials, tokens, and other secrets, exfiltrates them to attacker-controlled repositories, and can propagate using stolen credentials, with IOCs published and the malicious package revoked by Bitwarden.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.